Skip to content

Hamza AhmadPenetration Tester, Security Engineer, Builder

18-year-old penetration tester and builder working between Karachi and Dubai — offensive security by day, shipping products the rest of the time.

SCROLL
A NOTE FROM HAMZA
Who I am

Ibreakthingstounderstandthem,thenbuildwhatIwishexisted.Shippingthreesystemsat theedge ofsecurity&AI.

Away from the screen

Golf

8 handicap · Karachi Golf Club

Five years in. Best ideas happen on the back nine.

DJ

Afro house · Afro tech · Melodic techno

Massano, Argy, Anyma. It's about storytelling — selection, transitions, atmosphere.

Soccer & futsal

Striker

Weekend games to get off the screens and reset.

Travel & faith

15+ countries

US, UK, UAE, KSA, Qatar, Kuwait, Bahrain, Thailand. Prayer, reflection, time in Madinah — it keeps me grounded.

ALSO INTO — Gaming · Crypto markets · Discovering new music

How I work
  • Curious
  • Builder mentality
  • Security-first
  • Systems thinker
  • Learn by doing
  • Competitive with myself
  • Long-term focused
  • Ships over plans
01 — About

The work

I break things to understand them — then build what I wish existed.

I'm 18, working in offensive security between Karachi and Dubai — with Rewterz and SIRP — and building products at the intersection of security, AI, and everyday life. Most of it started because I wanted a better tool for myself: a scanner that thinks like an attacker, an assistant that actually runs my day, a platform that makes an organization legible.

I'd rather ship something imperfect, learn from real usage, and iterate fast than chase theoretical perfection. The two halves feed each other — testing shows me the failure modes worth building against, and building shows me how the systems I test are actually put together.

AVAILABLE FOR SECURITY WORK & COLLABORATIONS
Age
18
Based
Karachi · Dubai
Working with
Rewterz · SIRP
Languages
English · Urdu
Focus
Offensive security · AI · Products
How it breaks down
01

Testing

Web apps, APIs and the business logic underneath them — probed the way an attacker would, not the way a scanner would. Bug bounty on the side.

02

Building

Turning what I find by hand into something that runs without me. OmniScan and Operon both started as that problem.

03

Automating

I think in agents, workflows and validation pipelines — systems doing real work on a schedule rather than demos.

Toolkit
  • Python
  • FastAPI
  • React
  • AI
  • PostgreSQL
Systems in flight
0
Testing disciplines
0
02 — Projects

Selected work

3 systems in flight. Each one started as something I wanted to exist and couldn't find.

OmniScan interface
01AI Security · with SIRP
Building

OmniScan

An AI-powered web-app vulnerability scanner — scans, attacks, validates and reports, like an autonomous pentester that never gets bored on hour nine.

  • Python
  • FastAPI
  • React
  • AI
omniscan.sirp.io
HPA interface
02Personal AI OS
Live

HPA

My personal AI operating system — an assistant that runs my day by chat, by voice, and through a dashboard I actually open every morning.

  • Python
  • FastAPI
  • AI
hpa.hamzahmad.io
Operon interface
03Enterprise OS
Building

Operon

A multi-tenant platform that unifies how an organization runs — from HR to workflows — without ten disconnected tools.

  • Python
  • React
  • PostgreSQL
03 — Offensive security

Breaking in

I test real-world targets for the flaws that only surface when you think adversarially — the ones a scanner reports as clean.

Active bug-bounty hunter alongside client work. Findings stay with the client — what I publish is method, never data.

scope.txt
  • 01Web app pentesting
  • 02Broken authentication
  • 03Access control
  • 04Business logic
  • 05Bot-defense bypass
  • 06API security
  • 07_
How an engagement runs
  1. 01

    Recon

    Map the real attack surface — subdomains, endpoints, parameters, the hosts nobody remembers owning. Most findings start here.

  2. 02

    Mapping

    Understand the app the way its developers do: roles, flows, trust boundaries, and what each endpoint quietly assumes.

  3. 03

    Exploitation

    Chain what's actually reachable. A finding that can't be reached isn't a finding.

  4. 04

    Validation

    Reproduce it cleanly and prove impact, so nothing reaches a report that can't survive being questioned.

  5. 05

    Reporting

    Write it so it can be fixed — exact steps, real impact, and remediation that closes the class rather than the instance.

04 — Off the clock

The reel

RANGE WORK · 2026
Eight handicap, five years in, still chasing the swing.

Eight handicap, five years in, still chasing the swing.

ROOFTOP SET · 2026
Afro house on a Karachi rooftop, laptop and a Coke.

Afro house on a Karachi rooftop, laptop and a Coke.

BLUEWATERS · 2026
The Dubai half of the split.

The Dubai half of the split.

THE SETUP · 2026
Controller, mixer, monitors. Selection is the whole craft.

Controller, mixer, monitors. Selection is the whole craft.

OFF GRID · 2025
Phone off, trees on.

Phone off, trees on.

LATE NIGHT · 2026
The hour when most of the building actually happens.

The hour when most of the building actually happens.

05 — Story

How I got here

Hamza Ahmad
  1. 01

    Crypto

    Got into crypto around 15 — Bitcoin, Solana, and how blockchains actually work. That rabbit hole led to everything else.

  2. 02

    Security

    It pulled me into cybersecurity, and then into offensive security.

  3. 03

    Building

    Somewhere in there I realized I love building as much as hacking.

  4. 04

    Tools

    So I started making the tools I wished existed. Almost everything began as “why doesn't this exist yet?”

Long-term: build products people genuinely rely on.

  • Built a personal AI operating system before finishing my portfolio.
  • I think in agents, workflows and validation pipelines.
  • Best ideas tend to happen walking a golf course.
06 — Contact

Let's build somethingworth shipping.

If you have a system worth attacking or a product worth building, I want to hear about it.

me@hamzahmad.io